CVE-2010-1929: Buffer Overflow
Multiple stack-based buffer overflows in the jclient.JavanovelljclientJClientdefineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code via the (1) EnteredClassID or (2) NewClassName parameter to nps/servlet/webacc.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1929?
CVE-2010-1929 is considered to have a high severity rating due to its potential for remote code execution by authenticated users.
How do I fix CVE-2010-1929?
To fix CVE-2010-1929, update Novell iManager to version 2.7.3 FTF3 or later, which includes patches for the vulnerability.
What versions of Novell iManager are affected by CVE-2010-1929?
CVE-2010-1929 affects Novell iManager versions 2.7.0, 2.7.3, and 2.7.3 FTF2.
Can CVE-2010-1929 be exploited without authentication?
No, CVE-2010-1929 requires remote authenticated access for exploitation.
What type of vulnerability is CVE-2010-1929?
CVE-2010-1929 is a stack-based buffer overflow vulnerability.